TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.1.0
Category
Uncategorized
Folder size
0.07 MB
License
LGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-04 00:16:48
Authors
ACSONE SA/NV, Odoo Community Association (OCA)
Maintainers
ACSONE SA/NV, Odoo Community Association (OCA)
Committers
Moises Lopez, Iván Todorovich, Maksym Yankin, Weblate, OCA-git-bot, oca-ci, arantxa-s73
Odoo dependencies
odoo/odoo:
- web
Python dependencies
None
System dependencies
None
Required by
auth_api_key_group, base_rest_auth_api_key
Description
Authenticate http requests from an API key.

API keys are codes passed in (in the http header API-KEY) by programs
calling an API in order to identify -in this case- the calling program's
user.

Take care while using this kind of mechanism since information into http
headers are visible in clear. Thus, use it only to authenticate requests
from known sources.

For unknown sources, it is a good practice to filter out this header at
proxy level.

Odoo allows users to authenticate `XMLRPC/JSONRPC` calls using their API key instead of a password by native API keys (`res.users.apikey`). However, `auth_api_key` has some special features of its own such as:
- API keys remain usable even when the user is inactive, if enabled via settings (e.g., for system users in a shopinvader case).
- Supports dual authentication via Basic Auth and API_KEY in separate HTTP headers.
- Admins can manage API keys for all users

Given these advantages, particularly in use case like system user authentication, we have decided to keep the `auth_api_key` module

Code Analysis info_outline

Views touched (3)
XML IDNameModelTypeStatus
auth_api_key_form_view auth.api.key.form (in auth_api_key) auth.api.key form New
auth_api_key_tree_view auth.api.key.list (in auth_api_key) auth.api.key list New
res_config_settings_view_form res.config.settings.form.inherit res.config.settings form Inherits base_setup.res_config_settings_view_form
HTTP endpoints (0)

No HTTP endpoints found for this module.

Models touched (4)

New fields (4)
  • active Boolean
    compute='_compute_active' default=True readonly=False store=True
  • key Char
    default=<expr> help='The API key. Enter a dummy value in this field if it is\n obtained from the server environment configuration.'
  • name Char
    required=True
  • user_id Many2one → res.users
    comodel_name='res.users' help='The user used to process the requests authenticated by\n the api key' required=True string='User'
Public methods (3)
  • create(self, vals_list)
    @api.model_create_multi
  • generate_random_key(self, api_key_ids=None)
    Generate a key for records that do not have one yet. :param list api_key_ids: optional record IDs, mainly used by XML data function calls where the method is invoked on the model. :return: True when the operation completed.
  • write(self, vals)

New fields (0)

No new fields.

Public methods (0)

No public methods.

New fields (1)
  • archived_user_disable_auth_api_key Boolean
    help='If checked, when a user is archived/unactivated the same change is propagated to his related api key. It is not retroactive (nothing is done when enabling/disabling this option).' string='Disable API key for archived user'
Public methods (0)

No public methods.

New fields (1)
  • archived_user_disable_auth_api_key Boolean
    readonly=False related='company_id.archived_user_disable_auth_api_key'
Public methods (0)

No public methods.

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…